Legal Cyber Academy
Standard or guidanceFreeCurrent

Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations

Computer Crime and Intellectual Property Section, Criminal Division, U.S. Department of Justice · 2009 manual, still the version published on the CCIPS documents page · 2009

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The Justice Department's own manual on the Fourth Amendment and statutory rules governing searches of computers and the acquisition of electronic evidence, including warrant drafting, plain view, consent, and the Stored Communications Act and Pen/Trap provisions.

Who it is for, and when

Read it for the structure of the legal analysis and for its warrant language, which is still the starting point many federal agents and prosecutors work from. Defence counsel should read it to see what the government was trained to do. Examiners supporting criminal work should read the sections on search scope and on-site versus off-site review, which shape what they are authorised to examine.

What it does not cover

It is seventeen years old and predates Riley v. California, Carpenter v. United States, and the CLOUD Act, so substantial parts of its Fourth Amendment and stored-data analysis are superseded — nothing in it should be cited without checking current law. It is federal criminal procedure only, and it is not a forensic examination manual.

Go to the source

Open at justice.gov (opens in a new tab)

https://www.justice.gov/criminal/cybercrime/docs/ssmanual2009.pdf

Details

Type
Standard or guidance
Written for
Lawyers and courtsWorking examinerLawyers and courts, Working examiner
Publisher
Computer Crime and Intellectual Property Section, Criminal Division, U.S. Department of Justice
Version verified
2009 manual, still the version published on the CCIPS documents page
Year
2009
Topics
search-and-seizure, criminal-procedure, evidence-handling, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.

  • An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

  • NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

  • A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.

  • The federal sanctions rule for lost ESI. It applies only where information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it and it cannot be restored or replaced through additional discovery, and it reserves the severe measures — adverse inference, dismissal, default — for a finding that the party acted with intent to deprive another party of the information's use.